Show filters
535 Total Results
Displaying 481-490 of 535
Sort by:
Attacker Value
Unknown
CVE-2006-5908
Disclosure Date: November 15, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the login_user function in yans.func.php in Lucas Rodriguez San Pedro Yet Another News System (YANS) 0.2b allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.
0
Attacker Value
Unknown
CVE-2006-5678
Disclosure Date: November 03, 2006 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in common/visiteurs/include/library.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the lvc_modules_dir parameter. NOTE: CVE disputes this vulnerability, because the inclusion occurs in a function that is not called during a direct request to library.inc.php
0
Attacker Value
Unknown
CVE-2006-5523
Disclosure Date: October 26, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in common.php in EZ-Ticket 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ezt_root_path parameter.
0
Attacker Value
Unknown
CVE-2006-5310
Disclosure Date: October 17, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter.
0
Attacker Value
Unknown
CVE-2006-3966
Disclosure Date: August 01, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.
0
Attacker Value
Unknown
CVE-2006-3346
Disclosure Date: July 03, 2006 (last updated October 04, 2023)
SQL injection vulnerability in tree.php in MyNewsGroups 0.6 allows remote attackers to execute arbitrary SQL commands via the grp_id parameter.
0
Attacker Value
Unknown
CVE-2006-3087
Disclosure Date: June 19, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in EZGallery 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pUserID, (2) aid, (3) aname, (4) uid, and (5) m parameter in (a) common/galleries.asp; (6) aid, (7) aname, (8) uid, (9) m, (10) gp, and (11) g parameter in (b) common/pupload.asp; and (12) msg, (13) fn and (14) gp parameter in (c) common/upload.asp.
0
Attacker Value
Unknown
CVE-2006-3004
Disclosure Date: June 13, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone Manager allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in player.php and (2) keyword parameter when performing a search.
0
Attacker Value
Unknown
CVE-2006-2485
Disclosure Date: May 19, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the quezza_root_path parameter.
0
Attacker Value
Unknown
CVE-2006-2424
Disclosure Date: May 17, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the ezUserManager_Path parameter to ezusermanager_pwd_forgott.php, possibly due to an issue in ezusermanager_core.inc.php.
0